TIDYELF is malware associated with APT41. The provided content states that TIDYELF loaded the main WINTERLOVE component by injecting it into the iexplore.exe process. This indicates a process-injection capability used to execute or stage another malware component within a legitimate Windows browser process, likely for stealth and defense evasion. High-confidence details available from the content are limited to this behavior and association: TIDYELF is linked to APT41, targets Windows systems, and uses iexplore.exe as the host process for the injected WINTERLOVE payload. No additional infection vector, industry targeting, or indicators of compromise are provided in the source content.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
APT41 malware TIDYELF loaded the main WINTERLOVE component by injecting it into the iexplore.exe process.
1 distinct technique documented for this family, organized by ATT&CK tactic.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware used to inject and load the WINTERLOVE component into iexplore.exe.
APT41 malware that injects the WINTERLOVE component into iexplore.exe.
Loads its main component (WINTERLOVE) via process injection into iexplore.exe.
Malware attributed to APT41 that injects into iexplore.exe to load the WINTERLOVE component.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.